aoc
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process external puzzle data provided by the user.
- Ingestion points: Puzzle descriptions and data inputs are provided as context to the agent, as outlined in the workflow of SKILL.md.
- Boundary markers: The instructions do not specify any delimiters or safety guidelines to differentiate between task instructions and the untrusted puzzle data.
- Capability inventory: The agent is empowered to write and execute code and use development tools like the gh CLI.
- Sanitization: There are no methods described for sanitizing or validating the input data before processing.
- [COMMAND_EXECUTION]: The skill instructs the agent to use the gh CLI for algorithm research.
- Evidence: SKILL.md suggests using commands like
gh search code "heapq.heappush" --language=pythonto find implementations. This utilizes a well-known and trusted developer service.
Audit Metadata